Buffer overflow in fig2dev - CVE-2020-21683
Published: June 27, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the shade_or_tint_name_after_declare_color() function in fig2dev/dev/genpstricks.c when converting a xfig file into pstricks format. A remote attacker can pass a specially crafted file to the application and crash it.
Affected software
SUSE Linux Enterprise Workstation Extension
Ubuntu
fig2dev (Ubuntu package)
transfig
transfig-debuginfo
transfig-debugsource
How to mitigate CVE-2020-21683
fig2dev (Ubuntu package) - addressed in versions 1:3.2.6a-6ubuntu1.1+esm1, 1:3.2.7a-7ubuntu0.1+esm1, 1:3.2.8b-1ubuntu0.1~esm1, 1:3.2.9-3ubuntu0.1~esm1, 1:3.2.9-4ubuntu0.1
transfig - update to 3.2.8b-4.15.1
transfig-debuginfo - update to 3.2.8b-4.15.1
transfig-debugsource - update to 3.2.8b-4.15.1